AI has learned to find software bugs faster than people can, and the programmes that pay for them are straining. In a single week, the three biggest went three different ways.
Microsoft paid out a record sum. Apple slammed the door on how many bugs a researcher can file. Google quietly repriced the whole thing. All three were reacting to the same flood.
Microsoft paid more than $20m to 562 researchers over its latest bounty year, The Register reported, a record on both counts. A year earlier it was about $17m to 344. Microsoft blamed the “growing use of AI” in security research for the surge.
But it is not a clean comparison: the company also widened what counts as a bug halfway through the year.
Apple slams the door
Apple went the opposite way. It placed a cap and a 30-day cool-off on submissions through its security portal, and anyone who wants to file more must make a special request. The change came because AI-powered finds had overwhelmed its review teams and were drowning out human researchers, the Financial Times reported.
The cost is concrete. Security firm Bynario found a high-severity macOS flaw that let a remote attacker create files as root, then run commands as root. It could not report the bug quickly. It had already hit Apple’s cap after filing 50 bugs in three weeks, it wrote.
Apple reached out directly and patched it. The twist: Bynario had found the bug using AI.
Google reprices the hard bugs
Google took a third path. It rebuilt its Android and Chrome reward rules. Now it pays top money for the hard, novel exploits AI still cannot produce, and less for the routine ones it now can. It is retiring bonuses for techniques that “AI has made almost routine,” it said. It also wants short, concrete reproducers rather than the long write-ups AI churns out.
The economics break
The common thread is money. Bug bounties were built around scarce human expertise, and AI has made both finding a bug and describing it cheap. The same slop is poisoning the public vulnerability database. AI is also finding real flaws at scale, and hunting bugs as fast as it files noise.
For defenders, the upside is real. An AI bug-hunter helped find a master key to every database in Microsoft’s Azure Cosmos DB. Anthropic’s Claude turned up flaws in cryptographic algorithms that experts had missed. The problem is telling that signal from the flood. Each of the big three has now picked a different way to try, and none of them looks final.

